["]Redirection happens in both firefox and internet explorer. on the bottom of the screen, when trying to access a site, I see "google analytics". Looks new to me. I tried the fixes suggested - ATF cleaner, GooredFix and tdsskiller. I originally purchased Malwarebytes Anti Malware, but that no longer works either. I've attached the logs form gooredfix and tdsskiller
I appreciate any help you can give me - this is quite frustrating.
Sincerely,
Heidi
Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
A window will open on your desktop
if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
If nothing unusual is found just press Enter
A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
Please post the contents of that file.
NEXT
Please download DDS from either of these links
LINK 1 LINK 2
and save it to your desktop.
Disable any script blocking protection
Double click dds.pif to run the tool.
When done, two DDS.txt's will open.
Save both reports to your desktop.
βββββββββββββββββ Please include the contents of the following in your next reply:
DDS.txt Attach.txt.
NEXT
Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
Double click the exe file.
If it gives you a warning about rootkit activity and asks if you want to run scanβ¦click on NO, then use the following settings for a more complete scan.
In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<β ROOKIT" entries
OMG! I could not follow your very specific directions because it seems that I can no longer access firefox or internet explorer. I am able to connect to the internet but it directs me to a page that says internet explorer warning, visiting this site may harm your computer and the only link is to purchase anti virus software. On top of that, there are many pop up security alerts and sometimes a porn site appears. Tg I have a netbook to communicate with you. I hope you can help me save my PC.
Sincerely,
Heidi
reboot the ailing computer and start tapping F8 repeatedly upon reboot until an advanced menu appears > arrow up to "last Known Good Configuration" and select it
see if that works,
if not try that again, only this time select "safe mode with networking" see if you can run the programs now,
if not try this:
If you have an active internet connection, copy/paste the links below into your browser, don't click them or the rogue might redirect. If you don't have an active internet connection, download the tools from another machine, and transfer them to the affected machine via USB flash drive.
Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 3 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message. Run rkill repeatedly until it's able to do it's job. This may take a few tries. You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.
At this point, you should now be able to run analysis tools.
Once the tool has run, do NOT reboot the machine, and then try to run DDS and GMER.
If for some reason the machine reboots, repeat the process. Again, try not to restart the machine.
Thank you for your replies. I was able to run all of the tools in safe mode only. I have attached the logs for each. I hope these were not the last steps. Symptoms are still there. Thank you in advance.
If you can only run this program in safe mode - make sure you boot back into safe mode if the program reboots, so that it will produce a log:
Download ComboFix from one of the following locations: Link 1 Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi, I ran combo fix and am attaching the log. i started combo fix before i turned off verizon security. when combo fix directed me to turn it off, it wasn't in the task bar and when i located it, it was running in safe mode and there was no option to turn it off. I hope I didn't totally mess this up, I rebooted after saving the log to a flash drive. Same issue is occurring. Thank you in advance.
Sincerely, Heidi
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.
NEXT
submit a file to virustotal for analysis
Use the browse button on that page to navigate to the location of the file to be scanned.
In the right hand panel,
click on the file c:\windows\system32\licwmih.dll
then click the open button.
The file will now be displayed in the submit box.
Scroll down a bit and click "send file", wait for the results
If you get a message saying File has already been analyzed: click Reanalyze file now
Once scanned, copy and paste the link to the results page in your next reply.
Please do the same with the following file:
c:\documents and settings\All Users\Application Data\SupportSoft\DellSupportCenter\_default\data\f9cd5860-4b46-43fa-aa04-46ba9e956204\7e7d3c88-958b-4607-85a7-8c1cc5188887.1\NOTEPAD.EXE
NEXT
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As⦠Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save β¦
[external image: Posted Image]
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you.
Copy and paste the contents of the log in your next reply.
CAUTION:Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
hi catbyte,
I cannot access the web page for virustotal. when i try i get a page that says Internet Explorer Warning - visiting this web site may harm your computer. I also can't access from safe mode
Heidi